PT-2026-56852 · Pypi · Pymonocypher
CVE-2026-53720
·
Published
2026-07-09
·
Updated
2026-09-03
CVSS v4.0
5.1
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
pymonocypher versions prior to 4.0.2.8
Description
The
argon2i 32() function fails to verify the size of the nb blocks buffer. If the provided buffer is smaller than required by the API contract, the function may write beyond the buffer boundaries, potentially leading to heap corruption.Recommendations
Update to version 4.0.2.8.
As a temporary workaround, ensure a correctly sized
nb blocks buffer is provided.Exploit
Fix
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pymonocypher